A dangerous new cyberattack is affecting aviation, satellite communication, and transportation companies in the United Arab Emirates. Hackers are using a tricky type of malware called polyglot malware to infect computers. This malware installs a backdoor called Sosano, which lets attackers take control of the affected system and execute commands remotely.
Who is Behind This Attack?
Cybersecurity experts at Proofpoint discovered this attack in October 2024. They have linked it to a hacker group named UNK_CraftyCamel. Although the campaign is currently small, it is highly advanced and poses a serious risk to businesses.
Researchers also noticed similarities between this attack and previous cyber operations carried out by Iranian-linked hacking groups TA451 and TA455. However, this particular campaign seems to focus more on stealing information, which makes it unique.
What is Polyglot Malware?
Polyglot malware is a sneaky kind of cyber threat that can be interpreted in different ways by different programs. This means a single file can look like one thing to one program and something else to another.
For example, a file might act as an MSI installer on Windows but behave like a JAR file for Java. Most security software checks files based on one format, so they fail to detect the hidden malicious parts. This helps hackers bypass security systems and deliver harmful programs unnoticed.
In this case, the UNK_CraftyCamel hackers are using this trick to send malware while avoiding detection.
How the Attack Works
The hackers start their attack with phishing emails, which are fake messages designed to trick people. These emails appear to come from a real Indian electronics company, INDIC Electronics. Inside the email, there is a malicious link that takes victims to a fake website (indicelectronics[.]net), where they are tricked into downloading a ZIP file named "OrderList.zip."
This ZIP file contains:
1. A shortcut file (LNK) that looks like an Excel document.
2. Two PDF files called about-indic.pdf and electronica-2024.pdf.
But these PDF files are not what they seem—they are polyglot files containing hidden malware:
1. The first PDF hides a script (HTA code) that can execute harmful commands.
2. The second PDF contains a hidden ZIP archive, which allows the malware to stay undetected.
When the victim opens the shortcut file (LNK), it runs a command in the background that triggers the hidden script inside the first PDF. This leads to the execution of the second PDF, which then:
1. Modifies the Windows Registry to maintain access even after a restart.
2. Extracts and runs an encoded image file (JPEG) that secretly contains malware.
3. Decodes and activates a DLL file ("yourdllfinal.dll"), which is actually the Sosano backdoor.
Once Sosano is activated, it connects to a remote server (bokhoreshonline[.]com). This allows hackers to send commands, steal data, execute programs, and install more malware.
How to Stay Safe
To prevent such cyberattacks, companies should take multiple security measures, such as:
1. Blocking Suspicious Emails: Use email security tools to detect and remove harmful links and attachments before they reach employees.
2. Employee Awareness Training: Teach workers to identify phishing emails and avoid clicking on unknown links or opening suspicious files.
3. Restricting Dangerous Files: If file types like LNK, HTA, and ZIP are not required for daily work, companies should block them in emails to reduce risks.
4. Advanced Malware Detection: Security software should be able to scan files in multiple ways, ensuring that hidden malware is detected.
Cybercriminals constantly develop new ways to avoid security measures. Companies in aviation, satellite communications, and critical infrastructure should stay alert, update their cybersecurity strategies, and use advanced security tools to protect their systems.
The United Arab Emirates (UAE) is emerging as a beacon of innovation and technological advancement in the Middle East, and its commitment to cybersecurity is a vital element in shaping its hyper-connected future. As the UAE's digital footprint expands, so too does the potential for cyberattacks that could disrupt critical infrastructure and compromise sensitive data.
Recent statistics reveal a concerning increase in the UAE's vulnerability to cyber threats, including ransomware and DDoS attacks. In a joint report by the UAE government and CPX security, it was found that nearly 155,000 vulnerable points exist within the UAE, with Dubai being the most concentrated area. Insider attacks, where individuals within organizations misuse their access to steal data, are also a growing concern as the country embraces cloud computing and artificial intelligence.
The financial implications of data breaches in the Middle East have also surged, with the region ranking second only to the US in terms of breach costs. The average cost of a data breach in the Middle East exceeded $8 million in 2023, highlighting the urgent need for robust cybersecurity measures. However, a critical gap remains, as nearly a quarter of oil and gas companies and government entities in the region lack dedicated cybersecurity teams.
The UAE is actively addressing these challenges through a multi-pronged approach to enhance its cybersecurity shield. Here are the top cybersecurity trends shaping the UAE's digital landscape in 2024:
1. Advanced Threat Detection: The UAE recognizes the limitations of traditional security methods and is investing in advanced threat detection systems powered by artificial intelligence (AI), machine learning (ML), and behavioural analytics. This approach enables real-time identification and response to sophisticated cyber threats.
2. Public-Private Partnerships (PPPs) for Enhanced Security: The UAE is forging partnerships between the government and private sector to create a united front against cyber threats. Collaborations with organisations like the UN's ITU and leading cybersecurity firms demonstrate a commitment to sharing expertise and resources.
3. Cloud Security on the Rise: With the increasing reliance on cloud storage and processing, the UAE is experiencing a surge in cloud security solutions. This growth is driven by investments from cloud service providers, proactive government measures, and the need for enhanced protection against cyberattacks.
4. Cybersecurity Education and Training: The UAE is investing in cybersecurity education and training programs to equip professionals with the necessary skills to combat cyber threats. From specialised courses in universities to workshops for businesses, there is a concerted effort to build a strong cybersecurity workforce in the country.
5. Zero Trust Security Model Gaining Traction: The adoption of the zero-trust security model is growing in the UAE as businesses move away from traditional network perimeters. This model constantly verifies users and devices before granting access to resources, offering enhanced security in a more open, cloud-based environment.
6. Regulatory Compliance: The UAE has implemented stringent cybersecurity regulations to safeguard critical infrastructure and sensitive data. Adhering to these regulations is mandatory for organisations operating in the country, ensuring a baseline level of cybersecurity.
7. Quantum Cryptography: The UAE is investing in the research and development of quantum cryptography technologies to protect against future cyber threats posed by quantum computers. This cutting-edge approach leverages the principles of quantum mechanics to secure communications.
8. Focus on Critical Infrastructure Protection: Protecting critical infrastructure is a top priority in the META region, with specific measures being implemented to safeguard sectors such as energy, transportation, and healthcare systems. These measures are essential for maintaining national security and ensuring the continuity of essential services.
9. Growth of Cybersecurity Startups and Innovations: The META region is witnessing a surge in cybersecurity startups that are developing tailored solutions to address regional needs. Initiatives like Dubai's Innovation Hub and Saudi Arabia's cybersecurity accelerators are nurturing a conducive environment for these startups to thrive.
10. Cyber Threat Intelligence Sharing: Sharing cyber threat intelligence is increasingly important in the META region. Governments and organisations are establishing platforms for real-time sharing of threat information, enhancing collective cybersecurity defence.
As the UAE continues to advance in AI, PPPs, and cloud security, the question remains whether these advancements will stay ahead of the ever-evolving tactics of cybercriminals. The future of cybersecurity depends on the UAE's ability to adopt cutting-edge solutions and anticipate and adapt to the next wave of threats.
Major UAE government organizations including the Executive Council of Dubai, the Federal Authority for Nuclear Regulation, the Telecommunications and Digital Government Regulatory Authority, and important government programs like Sharik.ae and WorkinUAE.ae are among the victims of the purported attack. The UAE Space Agency, Ministry of Finance, and Ministry of Health and Prevention are among the other ministries impacted.
The threat actor released a few samples, claiming to have access to personally identifiable information (PII) belonging to different government personnel. These samples included the roles, genders, and email addresses of high-ranking individuals.
The threat actor purportedly posted screenshots of internal data from multiple prominent government agencies in the United Arab Emirates. The threat actor displayed samples of personally identifiable information (PII) including names, roles, and contact data, claiming to have obtained access to PII of high-ranking government personnel.
The threat actor's purported possession of samples raises questions about the safety of government employees and the integrity of national activities. The hacker's sudden appearance complicates the situation and raises questions about the accuracy of the statements made, but it may also point to a high-risk situation.
Such a compromise might have serious repercussions for public safety, national security, and the UAE's economic stability. The world's cybersecurity community is keeping a careful eye on the events and highlighting the necessity of a prompt and forceful government probe to determine the full scope of the hack and minimize any possible harm.
The hacker's sudden rise to prominence and lack of past experience or evidence of similar actions raises questions about the veracity of the claims.
There hasn't been any independent confirmation of the breach, nor have the UAE government or the impacted agencies addressed these allegations as of yet. For further details on the attacks, the Cyber Express team has gotten in touch with the Telecommunications and Digital Government Regulatory Authority (TDRA) in Dubai.
The vast number of impacted organizations and the type of purportedly stolen data point to a very sophisticated and well-planned operation, which is inconsistent with the image of a lone, inexperienced hacker.
To provide insight into the challenges faced by CISOs following a breach, cybersecurity firm Trellix surveyed over 500 security executives globally, revealing strategic analysis, eye-opening data, and practical viewpoints.
In their analysis, the Trellix researchers revealed that 96% of CISOs (who have suffered at least one security incident) believe in the need for improvements. However, 52% of the respondents claim that their organizations have meagre to no technical knowledge on how to tackle challenging security incidents.
According to the aforementioned survey, 48% of security leaders believe that their organizations are majorly based on manual processes, which eventually makes it more difficult to identify and fix cyberattacks quickly.
Moreover, 44% of respondents attribute the inability to tackle cybercrime to inadequately documented and executed procedures, while 44% caution that disjointed security controls result in a deficiency of context.
According to Jake Moore, global cybersecurity adviser at ESET, better investment in security is significantly crucial for companies, taking into account the increased sophistication in cyber activities.
"Furthermore, now with the introduction of AI threats we are seeing cyberattacks become even more relentless and powerful[…]Companies need to bear in mind that the cost of recovery from an attack usually outweighs the cost of preventive security measures,” he says.
Organizations find it challenging to identify and address cybersecurity problems due to a lack of technological resources, but it can also be challenging when security professionals are overworked or underequipped. More than half of those surveyed (52%) said that their organization's security problems were caused by vulnerabilities in their security capabilities.
However, nearly half of the respondents that they had not properly enabled their detection policies or configured their IT stacks. Forty percent more claimed that their security and IT systems do not provide "adequate visibility" of occurrences.
Moore further warns, "Neglecting cybersecurity in terms of the people and process can leave a business dangerously exposed to preventable or mitigable attacks with potentially severe consequences."
The framework was developed in response to the collapse of the cryptocurrency markets in 2022, which caused authorities worldwide to step up their efforts to establish or enforce protections and left businesses and investors worried about the future of cryptocurrencies.
These new regulations involve the authorities seeking necessary permits and licenses in order to provide users with one or more crypto-related services in Dubai. The framework is accompanied by seven activity-based rulebooks that specify standards based on the type of service supplied and four mandatory rulebooks for service providers, which Talal Tabbaa, founder of the regional cryptocurrency exchange CoinMENA, hailed as being "elegantly designed."
Dubai is one among the seven emirates of the United Arab Emirates with a goal to emerge as a global hub for crypto and blockchain activities, and in order to accomplish this it was courting companies to systemize the jurisdiction even before publishing its strategized rules for the sector.
In the wake of the new rules being published, the institutional crypto custody provider Hex Trust became one of the first to receive an operational green light from the emirate's watchdog, the Virtual Asset Regulation Authority. Stating the time before VARA, which was established in 2022, Mohamed Reda El Sheikh, head of compliance at Hex Trust for the Middle East and North Africa (MENA) says "We were waiting for a licensing framework. We were waiting for somebody with interest to take the responsibility."
However, these new regulations set up by Dubai are still a work in progress, because of their comprehensive nature, which allows for potential development. The emerging hub's new regulatory structure also reveals the expense of compliance in the area, which may make it more difficult for start-up businesses to locate there.
While Tabbaa called the licencing costs "peanuts" when compared to other operating costs like hiring staff or maintaining offices locally, and compliance fees are not something crypto companies focus on when looking to enter a market, even he acknowledges that some of Dubai's fees can be viewed as being on the expensive side.
A company seeking to provide exchange services is required to pay an application cost of 100,000 UAE dirham (US$27,200) and an annual supervision fee that is double that amount, says the document. The application fee does not guarantee acceptance, and if the business wishes to provide additional services such as custody, lending, or payments, it must submit additional licensing applications (at a 50% reduction off the application charge) and pay additional monitoring fees.
For comparison, the application fee in Abu Dhabi, another emirate of the UAE, is $20,000, while the yearly monitoring fee is $15,000. However, the Abu Dhabi Global Market (ADGM) stated in an email to CoinDesk that goes up if businesses seek to provide additional kinds of assets.
“Apart from any tokenized securities, under ADGM’s regulations, any crypto exchange that operates a spot or derivative market in relation to virtual assets (which include cryptocurrencies such as bitcoin and ether) will have to apply for a Multilateral Trading Facility license,” the ADGM said. Companies that are likely to operate MTFs must pay an application fee of $125,000 and an annual supervision fee of $60,000.
In Singapore, crypto exchanges that are not involved in fiat currencies usually apply for a Major Payments Institution license (for digital payment token service), which comes with a 10,000 Singapore dollar ($7,500) annual fee. Wherein, New York's BitLicense comes with a $5,000 application fee, although companies have reported bearing a cost of around $100,000 for time allocation, and legal and compliance fees.
Dubai’s fees, on the other hand, are much more reasonable for larger companies. Although, it may not be very sustainable for startups, says Irina Heaver, a crypto lawyer based in the UAE.
“However, I fully agree that Dubai needed to step up and to regulate the space, with so many bottom feeding scammers trying to establish here, enough is enough. Hopefully, these regulations will be used to really target those bad players,” Heaver said.